Question on Local Users Group on Windows 2003 Standalone & System3



We have a Windows 2003 server that will be placed in DMZ as a standalone
server with IIS for webpage. One of the vulnerabilities identified is the
permission settings on the IISADMPWD. It's recommended that if the directory
cannot be removed, then modify the permissions so that only the
Administrators & System have access to this folder. I noticed the Power Users
& Users group had access to this folder but were inherited from the
\system32\ folder. I removed the Power Users group from \system32\ as their
are no local user accounts in that group. However,when I look at the Users
group, I see the ASPNet, NT Authority\Authenticated Users, NT
Authority\Interactive accounts in their. If I remove the Users group from the
NTFS permissions on the \system32\ will that break access for some of these
accounts? The only users that will log on locally to this box are
administrators. There is no printing or file & print sharing.

I know I can just go to the IISADMPWD folder and deny access to the users.
But wanted to know if anything would break by removing the group from the
\system32\.

Thanks in advance for any help given.
.



Relevant Pages

  • Re: Compromised Server? Anyone recognize the suspect Services?
    ... I finally discovered that there was a whole folder structure under ... Event viewer shows normal logins, but I did not have it set to record ... there are a bunch of logins for Website Accounts created by the ... order to find those files on the Web Server I had to make sure that System ...
    (microsoft.public.windows.server.networking)
  • Re: More than one description in a message rule?
    ... serves and Do not download from the server as they gray out that box. ... > "If you use a rule that moves a message to another folder, ... > whole list of rules or just the rules (filters?) specified for that ... I use two different email accounts so I want to make one ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Permission migration to new domain
    ... The server will not be reloaded, ... So we need a way change all the existing permissions to ... DOMAIN_A\Accounts has access to the Accounts folder. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Windows 2003 file sharing and NTFS right
    ... department for so many shared folder, ... who is under IT Team group and users group. ... server served as file server, I have some problem of the file access ... Bob is put in Both Group1 and users group. ...
    (microsoft.public.windows.file_system)
  • Re: Windows 2003 file sharing and NTFS right
    ... Thanks for your time and reply, here are the txt fie I got after execute the ... who is under IT Team group and users group. ... server served as file server, I have some problem of the file access ... One shared folder named Folder1 ...
    (microsoft.public.windows.file_system)